Privacy Policy
This Privacy Policy sets out the rules for the processing of personal data of users of the website kacperkochan.dev, in performance of the information obligation under Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC ("GDPR").
General provisions
- Administrator
- Kacper Kochan - se7t.dev
- NIP
- 5632445012
- REGON
- 388994617
- Registered address
- Połaniecka 25/6, 22-100 Chełm, Poland
The Administrator of personal data within the meaning of Article 4(7) of the GDPR is the entity indicated above.
The Administrator has not appointed a Data Protection Officer. In all matters concerning the processing of personal data, contact should be made using the email address indicated above.
This Policy applies to the website available at kacperkochan.dev and to all personal data processed in connection with the use of that website.
Purposes, legal bases and retention periods
Personal data is processed for the following purposes:
a) Handling correspondence submitted through the contact form
- Scope of data
- Name, email address, selected subject of the message, and the content of the message
- Purpose
- Reviewing the content of the message and providing a reply
- Legal basis
- Article 6(1)(f) of the GDPR — the legitimate interest of the Administrator consisting in conducting correspondence addressed to the Administrator
- Retention period
- 3 years from the date of the last correspondence
b) Verifying that the contact form is not being completed by automated means
- Scope of data
- IP address and technical information concerning the user's browser
- Purpose
- Distinguishing a user from automated software, in order to prevent abuse of the contact form
- Legal basis
- Article 6(1)(f) of the GDPR — the legitimate interest of the Administrator consisting in counteracting abuse and maintaining the functionality of the contact form
- Retention period
- For the period necessary to achieve the purpose indicated above, determined by the retention cycle for logs and verification data applied by Cloudflare, Inc. as the processor
c) Ensuring the security and availability of the website
- Scope of data
- IP address, date and time of the request, technical information transmitted by the browser, and the content of the cookie referred to in section 7
- Purpose
- Delivering the content of the website, limiting the number of requests originating from a single IP address, distinguishing a browser operated by a person from automated software, and ensuring the security and correct operation of the website
- Legal basis
- Article 6(1)(f) of the GDPR — the legitimate interest of the Administrator consisting in ensuring the security and correct operation of the website
- Retention period
- For the period necessary to achieve the purpose indicated above, determined by the retention cycle for logs and verification data applied by Cloudflare, Inc. as the processor
Voluntary nature of providing data
Providing personal data is voluntary. Providing a name, an email address and the content of the message is, however, a condition for submitting the contact form. Failure to provide that data prevents the message from being sent and a reply from being given.
Recipients of personal data
Personal data may be disclosed to the following recipients:
- Cloudflare, Inc. (USA)
- Hosting of the website, the anti-spam verification mechanism, and delivery of messages sent through the contact form
- Proton AG (Switzerland)
- Operation of the email account to which those messages are delivered
Cloudflare, Inc. processes data on behalf of the Administrator as a processor within the meaning of Article 28 of the GDPR, under a data processing agreement concluded with that entity. Proton AG provides the email service to the Administrator and processes the data contained in the messages delivered to that mailbox to the extent necessary to provide that service, on the terms set out in its own terms of service and its own privacy policy.
Personal data is not sold, is not disclosed for marketing purposes, and is not made available to any other entities, except where the obligation to disclose it arises from generally applicable provisions of law.
Transfers of data to third countries
Cloudflare, Inc. has its registered office in the United States of America. Transfers of personal data to that entity take place on the basis of the European Commission's adequacy decision in respect of the EU–US Data Privacy Framework (Article 45 of the GDPR) and, in addition, on the basis of the standard contractual clauses referred to in Article 46(2)(c) of the GDPR, incorporated into Cloudflare's data processing addendum.
Owing to the distributed nature of the network operated by that entity, data may also be processed in other countries in which that entity maintains its infrastructure; such transfers are covered by the safeguards indicated above. A copy of the standard contractual clauses may be obtained at the following address:
- Copy of the clauses
- www.cloudflare.com/cloudflare-customer-dpa
Proton AG has its registered office in the Swiss Confederation, in respect of which the European Commission has determined that an adequate level of protection of personal data is ensured, in accordance with Article 45 of the GDPR. The application of additional safeguards is not required in that case.
Rights of the data subject
The data subject has the right to:
- access their personal data and obtain a copy of it (Article 15 of the GDPR);
- obtain rectification of personal data which is inaccurate (Article 16 of the GDPR);
- obtain erasure of personal data (Article 17 of the GDPR);
- obtain restriction of processing of personal data (Article 18 of the GDPR);
- object to the processing of personal data carried out on the basis of the legitimate interest of the Administrator (Article 21 of the GDPR).
The Administrator separately draws attention to the right to object: as every processing operation described in this Policy is based on Article 6(1)(f) of the GDPR, the data subject may object at any time, on grounds relating to their particular situation, to the processing of their personal data. Upon receipt of an objection the Administrator will no longer process the data concerned, unless the Administrator demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or grounds for the establishment, exercise or defence of legal claims (Article 21(1) of the GDPR).
The above rights are exercised on the basis of a request sent to the email address indicated in section 1. The Administrator provides a response without undue delay and in any event within one month of receipt of the request. That period may be extended by two further months where necessary, by reason of the complexity of the request or the number of requests; the Administrator informs the data subject of any such extension, together with the reasons for the delay, within one month of receipt of the request (Article 12(3) of the GDPR).
The data subject additionally has the right to lodge a complaint with the supervisory authority:
- Authority
- Prezes Urzędu Ochrony Danych Osobowych
- Address
- ul. Stanisława Moniuszki 1A, 00-014 Warszawa
- Website
- uodo.gov.pl
Cookies and terminal equipment
The website uses one cookie, described below. Apart from that cookie, the website does not store information on, and does not gain access to information already stored in, the user's terminal equipment.
- Name
- cf_clearance
- Set by
- Cloudflare, Inc. — the entity indicated in section 4 — as part of the mechanism designated by that provider as JavaScript Detections. The cookie is stored under the domain kacperkochan.dev and is read only by that domain.
- Purpose
- Recording the result of an automated check of whether a request originates from a browser operated by a person rather than from automated software, for the purpose and on the legal basis indicated in section 2(c)
- Scope of application
- Every page of the website. The mechanism operates at the level of the infrastructure provider and is not limited to the contact form
- Storage period
- Short-lived; the expiry is set by Cloudflare, Inc. and the cookie is issued again on subsequent visits
That cookie does not serve analytical, advertising or tracking purposes. It is not used to identify the user on any other website, its content is not combined with data from any other source, and no marketing profile is created on its basis.
In the assessment of the Administrator, storing that cookie is strictly necessary in order to provide the service explicitly requested by the user, and is therefore covered by the exemption from the consent requirement provided for in the provisions of the Electronic Communications Law implementing Article 5(3) of Directive 2002/58/EC. For that reason the website does not present a consent request. Should that assessment change, this Policy will be amended and the user's consent obtained before the cookie is stored.
The contact page loads the anti-spam verification mechanism referred to in section 2(b) from the domain challenges.cloudflare.com, including its subdomains, which is operated by Cloudflare, Inc. Displaying and operating that mechanism causes the user's browser to connect to that domain and to transmit to it the data indicated in section 2(b). That processing is carried out by the entity indicated in section 4, on the terms set out in sections 4 and 5.
No other page of the website loads resources from a domain other than its own. Typefaces, style sheets and scripts are served from the website's own domain, as is the script of the mechanism described in the table above, although that script originates from the provider indicated there. The website in its entirety, including those resources, is delivered through the content delivery network of the entity indicated in section 4, which is the hosting of the website referred to in that section.
The website does not store data in the browser's local storage (localStorage, sessionStorage).
Automated decision-making and profiling
Personal data is not subject to automated decision-making, including profiling, as referred to in Article 22 of the GDPR.
The Administrator does not use analytical, advertising or tracking tools, and does not combine data collected through the website with data from any other source.
Security of processing
The Administrator applies technical and organisational measures appropriate to the risk of infringement of the rights and freedoms of data subjects, in accordance with Article 32 of the GDPR.
In particular, data transmitted between the user's browser and the server is encrypted using the TLS protocol, and the contact form endpoint is subject to a limit on the number of requests originating from a single IP address.
Amendments to the Policy
The Administrator reserves the right to amend this Policy. The date of the last amendment is indicated at the beginning of the document.
Amendments of a purely editorial nature which do not affect the rules for the processing of personal data do not result in a change to that date.